Deep Graph Learning Architecture for Real-Time Cyber Threat Identification and Detection in Cloud Platforms
Abstract
The rapid adoption of cloud computing has transformed enterprise information infrastructures into highly dynamic environments characterized by distributed resources, elastic workloads, interconnected services, and continuously changing user and application behavior. These characteristics increase the complexity of identifying cyber threats because malicious activities frequently propagate across multiple entities rather than appearing as isolated events. Conventional machine-learning approaches that treat security observations independently can therefore overlook relational dependencies among users, virtual machines, applications, network flows, and cloud services. This paper proposes a Deep Graph Learning Architecture for Real-Time Cyber Threat Identification and Detection in Cloud Platforms, positioning cloud security monitoring as a graph-based learning problem. The proposed architecture integrates graph construction, deep graph representation learning, adaptive threat classification, continual learning, and real-time alert generation. The theoretical design is informed by research on continual learning, adaptive regularization, domain adaptation, task-aware learning, memory-aware learning, and graph-based cyber-threat identification. Particular emphasis is placed on maintaining detection performance under evolving attack distributions while limiting catastrophic forgetting. The framework conceptualizes cloud entities as graph nodes and their interactions as dynamically updated edges, enabling the model to capture structural and behavioral relationships. Analytical findings indicate that combining relational representations with continual adaptation can improve the suitability of threat detection systems for evolving cloud environments, although computational overhead, graph scalability, concept drift, and uncertainty remain important limitations. The study contributes an integrated research architecture for real-time cloud threat identification and establishes a foundation for adaptive graph-based cybersecurity systems.